Type something to search...
Extend Zero Trust to AI agent identities in Entra ID

Extend Zero Trust to AI agent identities in Entra ID


Introduction

AI agents are becoming increasingly widespread in businesses (incident summaries, log analysis, flow execution, etc.), and it is crucial that their access is continuously evaluated and limited to what is strictly necessary. Microsoft is introducing conditional access policies to apply Zero Trust controls to AI agents and other non-human identities. The goal is to determine, for each token request, whether an agent can access a resource based on its identity, risk, and context.

Microsoft Entra now treats agents as first-class identities and extends Conditional Access to their authentication flows to limit abuse and misuse.


What is an agent identity ?

Microsoft Entra formalizes three concepts:

  1. Agent Blueprint : A template for creating agent identities
  2. Agent Identity : A specialized machine identity for AI systems
  3. Agent User : An identity whose behavior is the same as a human’s

What is possible today

Conditional access allows for identity-based, risk-based, and context-based controls to be applied before granting access, but for AI agents, capabilities are intentionally limited at the moment.

image

Supported features

  • Identity targeting : Agents can be included/excluded from rules
  • Access blocking : The only control currently available
  • Agent risk : Simple risk level assessment
  • Request assessment : Token requests are checked

Features not currently available

  • MFA and authentication strength
  • Device compliance
  • Approved client applications
  • Application protection rules
  • Session or location conditions
  • Connection frequency and terms of use

How conditional access works for agents ?

When an agent identity or an agent user requests a token, Microsoft Entra follows this process :

  1. Identify the requesting agent
  2. Check conditional access rule assignments
  3. Evaluate any agent risk criteria
  4. Allow or block token issuance

No MFA prompt, no device verification, no strong authentication evaluation — just a block or allow decision based on identity and risk.


Practical use cases

Even with these limitations, conditional access rules for agents can be useful :

  • Stop compromised agents : If an agent exhibits high-risk behavior, the token request is immediately blocked, stopping any unauthorized action.
  • Separate agent roles : You can define rules to allow certain specific agents while blocking others, depending on the department or use case.
  • Limit agent sprawl : In large organizations, hundreds of agents can be created; only approved agents can access resources.

Required licenses
  • Conditional access requires the Microsoft Entra ID P1 license (included in Microsoft 365 E3 and Microsoft 365 Business Premium).
  • Policies based on risk-based signals require the Microsoft Entra ID P2 license (included in Microsoft 365 E5). Ensure that each identity targeted by the policy has the appropriate license.

Future outlook

Microsoft indicates that agent capabilities could evolve toward :

  • More sophisticated agent risk scoring
  • Behavioral analytics
  • More granular granting controls
  • Targeted policies per task or per capability

Conclusion

With conditional access policies for agent identities, Microsoft Entra brings to the world of AI agents the same adaptive access guarantees as for people and applications : signal → decision → application. Even though controls are intentionally limited in this first iteration, the architecture (attributes, blueprint targeting, dedicated logs) provides a robust framework for industrializing agent security… without slowing adoption.


Sources

Microsoft - Techcommunity

Microsoft Learn - Microsoft Entra licenses


Did you enjoy this post ? If you have any questions, comments or suggestions, please feel free to send me a message from the contact form.

Don’t forget to follow us and share this post.

Related Posts

Email verification of external Teams participants

Email verification of external Teams participants

Introduction Microsoft Teams Premium introduces a new feature to enhance the security and reliability of your meetings: email verification for external participants. This feature allows mee

Read More
Nearly 70% of Fortune 500 companies use Copilot

Nearly 70% of Fortune 500 companies use Copilot

Introduction At Microsoft Ignite 2024, Microsoft highlighted why nearly 70% of Fortune 500 companies now use Microsoft 365 Copilot. This mass adoption reflects a growing trend in the indu

Read More
How to disable self-service on Copilot licenses

How to disable self-service on Copilot licenses

Introduction Microsoft has activated a setting in the tenants (by default) to allow any user to purchase a Microsoft Copilot license through the *Microsoft 365 Copilot self-service pursha

Read More
How to activate Microsoft 365 Passkey in Entra ID

How to activate Microsoft 365 Passkey in Entra ID

Introduction Microsoft 365 Passkey is an authentication method that replaces passwords with more secure options like facial recognition, fingerprint, or a PIN.Prerequisites **<

Read More
How to sign in with Passkey to Microsoft 365

How to sign in with Passkey to Microsoft 365

Introduction Microsoft 365 Passkey is an authentication method that replaces passwords with more secure options like facial recognition, fingerprint, or a PIN.Prerequisites **<

Read More
Improved Teams video quality with Super Resolution

Improved Teams video quality with Super Resolution

Introduction Microsoft continues to innovate to provide users with the best possible virtual communication experience. One of the latest advancements is the introduction of *Super Resolutio

Read More
Le Chat by Mistral AI, your personal AI assistant

Le Chat by Mistral AI, your personal AI assistant

Introduction I told you last December about the French AI, Mistral AI, the most popular model in Europe in which Microsoft invested 15 million euros in the startup. The mobile app has jus

Read More
New Yealink MeetingBoard 65 and 85 for Teams rooms

New Yealink MeetingBoard 65 and 85 for Teams rooms

Introduction The new Yealink MeetingBoard 65 and 85 are an innovative and comprehensive solution designed to transform meeting rooms into intelligent collaboration spaces. These all-in-on

Read More
How to enable LAPS on the MTR Admin account via Intune

How to enable LAPS on the MTR Admin account via Intune

Introduction Microsoft's LAPS (Local Administrator Password Solution) is a free tool designed to improve password security for local administrator accounts on workstations, servers and

Read More
Maximize the use of the Copilot prompt gallery

Maximize the use of the Copilot prompt gallery

Introduction Microsoft 365 Copilot continues to revolutionize the way organizations work by integrating advanced artificial intelligence capabilities into everyday tools. One of the key f

Read More
How to get started with Copilot in Excel

How to get started with Copilot in Excel

Introduction Microsoft 365 Copilot is a major innovation that integrates artificial intelligence directly into the applications you use every day, like Excel. Copilot helps you automate t

Read More
Microsoft Purview for Azure Data Lake and Blob Storage

Microsoft Purview for Azure Data Lake and Blob Storage

Introduction Microsoft announced that Microsoft Purview protection policies for Azure Data Lake and Blob Storage are now available in all regions. This advancement allows organization

Read More
Facilitator, new AI agent for taking notes in meetings

Facilitator, new AI agent for taking notes in meetings

Introduction Microsoft recently announced a new feature for Teams Rooms: Facilitator ; an AI agent that takes notes during Teams meetings. This feature is currently in pre-public release

Read More
Impact analysis of Entra ID conditional access policies

Impact analysis of Entra ID conditional access policies

Introduction Conditional access in Entra is a security policy that allows administrators to control access to applications and resources based on specific conditions. These conditions can i

Read More
Enterprise Connect 2025 : Yealink SkySound CM50 Dante kit

Enterprise Connect 2025 : Yealink SkySound CM50 Dante kit

Introduction Enterprise Connect is an annual conference that brings together communications technology professionals, innovators, and others. This event showcases technological advances i

Read More
How to create a Windows local admin account via Intune LAPS

How to create a Windows local admin account via Intune LAPS

Introduction I wrote an article last February on how to replace the password of your MTR's local account using LAPS (Local Administrator Password Solution) in Intune. I concluded my article

Read More
New security approach for non-compliant emails

New security approach for non-compliant emails

Introduction Microsoft has announced a major update to Defender for Office 365 that strengthens email security by improving the handling of non-RFC compliant emails. This initiative is

Read More
Mistral OCR, new benchmark in character recognition

Mistral OCR, new benchmark in character recognition

Introduction In March 2025, Mistral AI announced the launch of Mistral OCR, an optical character recognition (OCR) API that sets a new standard in document understanding. This advance

Read More
Introducing the Logitech Rally Board 65

Introducing the Logitech Rally Board 65

Introduction The Logitech Rally Board 65 is an all-in-one video conferencing solution designed to simplify meetings and collaboration in business environments. With its 65-inch touchscree

Read More
Blocking screenshots during Teams meetings

Blocking screenshots during Teams meetings

Introduction Microsoft Teams continues to strengthen the privacy and security of online meetings. Starting in July 2025, a new feature will be rolled out to prevent screenshots during meeti

Read More
"Anti-Tampering" certification for Defender for Endpoint (2025)

"Anti-Tampering" certification for Defender for Endpoint (2025)

Introduction Microsoft recently announced that Microsoft Defender for Endpoint has successfully passed the 2025 anti-tampering tests conducted by AV-Comparatives, a recognized independe

Read More
Mistral Code, the European AI development assistant

Mistral Code, the European AI development assistant

Introduction French startup Mistral AI, already recognized for its open source language models, has just unveiled Mistral Code, an intelligent development assistant designed for businesse

Read More
How to enable DLP for Teams with Purview

How to enable DLP for Teams with Purview

Introduction In a context where sensitive data, particularly banking information, is increasingly circulating in collaborative tools, businesses must be extra vigilant to avoid accidental o

Read More
New Yealink MeetingBar A50 for Teams Rooms

New Yealink MeetingBar A50 for Teams Rooms

Introduction In an increasingly hybrid work world, businesses are looking for video conferencing solutions that are powerful, easy to deploy, and seamlessly integrated into their *Microsoft

Read More
Mercedes-Benz, your car becomes a rolling office

Mercedes-Benz, your car becomes a rolling office

Introduction In an automotive market increasingly focused on smart and connected mobility, Mercedes-Benz is taking a giant leap forward. With the new generation of the CLA model, the Ge

Read More
How to enable DLP for Outlook with Purview

How to enable DLP for Outlook with Purview

Introduction Last week, I showed you how to enable DLP for Teams with Microsoft Purview to prevent accidental or malicious data leaks (Data Loss Prevention). Purview is a comprehensive

Read More
Anthropic unveils Claude Opus 4.1, faster and more reliable

Anthropic unveils Claude Opus 4.1, faster and more reliable

Introduction Anthropic, a leading player in artificial intelligence, has announced the release of Claude Opus 4.1, a significant update to its flagship model (Claude Opus 4). Designed

Read More
OpenAI unveils GPT-5, its latest smarter model

OpenAI unveils GPT-5, its latest smarter model

Introduction OpenAI has taken another step forward in the evolution of artificial intelligence with the launch of GPT-5, its most powerful language model to date. Designed to be smarter

Read More
Entra Private Access for Domain Controllers

Entra Private Access for Domain Controllers

Introduction Microsoft has announced the Public Preview of Microsoft Entra Private Access for Active Directory Domain Controllers, a major step forward in strengthening the security of

Read More
What's new for Copilot in August 2025

What's new for Copilot in August 2025

Introduction Microsoft releases a monthly update to Microsoft 365 Copilot to keep admins and users up-to-date on productivity-enhancing features in Microsoft 365. The August 2025 release

Read More
Anthropic unveils Claude Sonnet 4.5, more advanced

Anthropic unveils Claude Sonnet 4.5, more advanced

Introduction Anthropic, a leading player in artificial intelligence, has announced the release of Claude Sonnet 4.5, touted as the world's best coding model and a significant leap for

Read More
How to activate Defender EDR in "Block Mode"

How to activate Defender EDR in "Block Mode"

Introduction In a context of constantly evolving cyber threats, antivirus solutions are no longer sufficient to effectively protect workstations. Microsoft Defender for Endpoint's *Block

Read More
How to enable DSPM for AI with Purview

How to enable DSPM for AI with Purview

Introduction With the rise of generative AI models, the phenomenon of Shadow AI (the use of artificial intelligence tools and services not approved or controlled by organizations) is incr

Read More
How to block a website URL in Edge with Defender

How to block a website URL in Edge with Defender

Introduction Web browsing is one of the most common attack vectors in business environments. To strengthen security, Microsoft Defender for Endpoint offers a powerful feature : blocking m

Read More
How to enable DLP for cloud storage with Purview

How to enable DLP for cloud storage with Purview

Introduction A few months ago, I showed you how to enable DLP for Outlook with Microsoft Purview to prevent accidental or malicious data leaks (Data Loss Prevention). Purview is a com

Read More
How to add a disclaimer in Copilot

How to add a disclaimer in Copilot

Introduction Microsoft has enabled a setting in tenants that allows administrators to display the Microsoft 365 Copilot disclaimer in bold, and to attach a shortcut pointing to a usage po

Read More
How to enable DLP for printing with Purview

How to enable DLP for printing with Purview

Introduction A few weeks ago, I showed you how to enable DLP to prevent the copying of financial data to an external cloud storage solution using Microsoft Purview, in order to prevent

Read More
Mistral Voxtral Transcribe2, real-time transcription

Mistral Voxtral Transcribe2, real-time transcription

Introduction Mistral AI has just unveiled Voxtral Transcribe 2, its second generation of speech transcription models with cutting-edge transcription quality, ultra-low latency and advan

Read More
How to enable DLP for AI websites with Purview

How to enable DLP for AI websites with Purview

Introduction Last week, I showed you how to enable DLP to prevent printing of financial data using Microsoft Purview, in order to prevent accidental or malicious data leaks (*Data Loss

Read More
Anthropic unveils Claude Opus 4.6, a benchmark for finance

Anthropic unveils Claude Opus 4.6, a benchmark for finance

Introduction Artificial intelligence is rapidly growing in the finance industry, but one reality remains : real-world financial analyses are rarely clean, linear, or perfectly defined. They

Read More
How to enable Claude AI as a model in Copilot

How to enable Claude AI as a model in Copilot

Introduction Since its launch, Microsoft 365 Copilot has established itself as a cornerstone of enhanced enterprise productivity, leveraging advanced AI models to reason, analyze, and aut

Read More
How to enable DLP for copy/paste with Purview

How to enable DLP for copy/paste with Purview

Introduction Last month, I showed you how to enable DLP to prevent financial data from being sent to an AI website using Microsoft Purview, in order to prevent accidental or malicious d

Read More
OpenAI unveils GPT-5.4, the new generation of models

OpenAI unveils GPT-5.4, the new generation of models

Introduction OpenAI has just announced GPT-5.4, a new evolution of its GPT model family. Designed for professional uses and complex tasks, this model introduces several major improvemen

Read More
Introducing Microsoft 365 E7, the Frontier Suite

Introducing Microsoft 365 E7, the Frontier Suite

Introduction Microsoft has announced the availability of the Microsoft 365 E7 license, a new offer called Frontier Suite, designed for the era of AI-driven work and agents. This announc

Read More
Purview Sensitivity Labels are coming to OneNote

Purview Sensitivity Labels are coming to OneNote

Introduction Good news for security and compliance teams, Sensitivity Labels are now General Availability in OneNote. This update finally allows you to apply the same classification a

Read More
How to block Teams calls and chats with Purview IB

How to block Teams calls and chats with Purview IB

Introduction Microsoft Purview's Information Barriers allow you to restrict communication and collaboration between specific user groups within a Microsoft 365 environment. Their prim

Read More
End of implicit internet access for new Azure VNets

End of implicit internet access for new Azure VNets

Introduction Starting March 31, 2026, Microsoft is making a major change to Azure's default network behavior. New Virtual Networks (VNet) will no longer have implicit outbound internet

Read More
External MFA is now available in Entra ID

External MFA is now available in Entra ID

Introduction Microsoft has announced the General Availability of External MFA, in Microsoft Entra ID, formerly known as External Authentication Methods. This feature allows the use

Read More
How to create Sensitivity Labels for emails in Purview

How to create Sensitivity Labels for emails in Purview

Introduction Emails remain one of the primary vectors for information leaks in businesses. Whether it's a message sent to the wrong recipient, an attachment forwarded without proper oversig

Read More